Port 12345NetBus / NetBuster

Port 12345 is strongly associated with the NetBus remote administration tool, which is widely known as a backdoor Trojan horse. It was originally designed for legitimate remote control but was quickly adopted by malicious actors for unauthorized access and control over infected machines. Additionally, this port has seen use by NetBuster, a NetBus honeypot tool, and is sometimes used by certain networked games such as Little Fighter 2..

transport
unknown

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
19,893

rank 126 of 993 · top 13%

Technical Details

what runs on :12345

Port 12345 historically became infamous due to its association with NetBus, a Windows-based remote administration tool released in the late 1990s. The software includes a server component, which runs on the target machine and listens by default on TCP port 12345, awaiting connections from the client's control software. The tool allows remote interaction, screen control, file system access, keystroke logging, and more, making it both a potent utility and a dangerous Trojan horse if deployed surreptitiously.

Unlike legitimate administration software like VNC or RDP, NetBus was widely abused as a backdoor, often installed unknowingly to the victim, giving attackers unfettered access without explicit permission. Because of its default port, 12345 became synonymous with suspicious or malicious remote access activity.

In response, some security researchers developed tools such as NetBuster, which acts as a honeypot by simulating a NetBus server on port 12345, to catch or log intrusion attempts. The port also has incidental, benign uses, notably by the game Little Fighter 2. However, these are far less common and the port typically raises red flags in network security contexts.

Security Information

exposure of :12345

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

unknown

every listening transport is another surface to filter at the edge

security overview

Common vulnerabilities:

  • Unauthorized remote control if NetBus or similar Trojans infect a machine.
  • Credential theft through keylogging or screen monitoring once the attacker has connected.
  • Lateral movement by attackers leveraging the backdoor to install further malware.
  • Port scans to detect open 12345 often indicate reconnaissance activity by threat actors.

Common mitigations:

  • Block inbound and outbound traffic on port 12345 at network perimeters unless explicitly required.
  • Run antivirus and anti-malware solutions capable of detecting NetBus or similar threats.
  • Use intrusion detection and honeypot strategies (like NetBuster) to monitor suspicious activity.
  • Regularly audit open ports and running services on systems to ensure unauthorized software is not operating.
  • Educate users about social engineering and malware to reduce initial infection risks.

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted